Customer AI Control Plane
The Customer AI Control Plane is the customer-controlled boundary between an AI Team and the organization’s operating environment.
It is not synonymous with an MCP server, data connector, or knowledge base. Those can be implementation components. The control plane is the broader mechanism that tells the AI workforce how the organization works, where authorized information lives, who may access it, and what actions are permitted.
Organizational context
The control plane can provide instructions such as:
- where different classes of information are stored
- which systems or repositories are authoritative
- organizational terminology and taxonomy
- how to locate approved information
- which workflow or business rules apply
- when work must escalate to a person
This creates an organizational map without forcing all enterprise information into model context.
Identity and access
The control plane can govern:
- human identities and roles
- Digital Employee identities and roles
- permissions and entitlements
- data access
- tool and system access
A Digital Employee’s technical access should not automatically become every human user’s access.
Effective authorization
Access can be evaluated from both sides of the interaction:
Human authorization ∩ Digital Employee authorization = permitted access or action
For example, a Digital Employee may be authorized to retrieve sensitive capture information for an executive but prohibited from returning the same information when directed by a user without that entitlement.
Governance and policy
The control plane can also express:
- approval requirements
- action boundaries
- audit and logging requirements
- retention and security controls
- source requirements
- escalation rules
See AI Agent Governance and Controls.
Implementation flexibility
The Customer AI Control Plane may use MCP servers, native enterprise controls, APIs, connectors, identity systems, policy engines, customer instructions, or an organization’s existing AI infrastructure.
The architecture is deliberately independent of any single protocol.
See MCP and AI Teams for one implementation mechanism.